ISO 27001 or NIS2 first?
A customer wants ISO 27001 and NIS2 is on the way. Build one management system, let the paying deadline set the order, and the same work carries both.
A customer wants ISO 27001 certification. NIS2 duties are heading for your sector or your contracts. Fund those as two separate projects and you pay twice for work that is mostly identical. Our advice is short: build one management system for information security, let it carry both, and let the paying deadline decide the order.
I meet the same question in compliance conversations this year: which one first, and how do we avoid paying double? The worry is fair. The names sound like two regimes, and I have seen projects scoped as if they were.
What separates ISO 27001 from NIS2
ISO 27001 is the international standard for running information security as a managed system, an ISMS. The current version is ISO/IEC 27001:2022. It is certifiable: an accredited certification body audits the system and issues a certificate, which is why a customer or a tender can require it. No law forces you to hold the certificate. The pressure is commercial.
NIS2 is the EU’s cybersecurity directive, Directive (EU) 2022/2555. It gives covered organisations legal duties: manage your cyber risk, report serious incidents fast, and put the management body (your board and top leadership) on the hook for both. There is no certificate to obtain. A regulator checks compliance, not an auditor you hire.
NIS2 reaches Norwegian businesses along two routes. Norway is in the EEA, incorporation of the directive is in progress, and no start date is announced, so the sector duty arrives through Norwegian law later. The supply chain moves faster: covered customers must manage the risk from their suppliers (Article 21), so the security questionnaire can land on your desk long before the law names you.
The work overlaps more than the names do
Strip the labels off and the day-to-day work is close to identical. Article 21(2) of NIS2 lists the measures covered organisations must have: policies for risk analysis, incident handling, continuity and backup, supply chain security, access control, encryption and training, plus a way to measure that it all works. Annex A of ISO 27001 covers the same ground with its 93 controls, and the standard’s working method (assess the risk, treat it, document it, improve it) is the discipline NIS2 expects.
The directive itself points the same way: Article 25 encourages the use of European and international standards. In practice, an ISMS built to ISO 27001 produces the risk assessments, the controls and the evidence that both the auditor and the regulator ask for. You write the documentation once and present it twice.
What NIS2 requires beyond ISO 27001
The difference is real, but small enough to plan for. Two things carry it.
First, incident reporting on a legal clock. NIS2 (Article 23) requires an early warning to the authorities within 24 hours of learning about a serious incident, a fuller notification within 72 hours, and a final report within a month. ISO 27001 requires you to handle incidents but sets no statutory deadlines. Your ISMS needs a reporting procedure with named roles and rehearsed timelines.
Second, management accountability. NIS2 (Article 20) requires the management body to approve the risk measures, follow up that they work, and take training, and it opens the door to personal liability if the duties are neglected. ISO 27001 demands leadership commitment, but the certificate does not make your directors legally accountable. The fix is a governance routine: put approval and follow-up of the ISMS on the board agenda and minute it.
Both additions fit inside the system you already built. They are procedures and agenda points, and they do not require a second project.
Let the paying deadline set the order
If a paying customer or a live tender requires ISO 27001, the order is already decided. Fund the ISMS now, run it until you are certification-ready, and fold the NIS2 pieces (the reporting procedure, the board follow-up) into the same system as you build it. The certificate wins the contract, and the NIS2 documentation falls out of work you were paying for anyway.
If no customer is asking yet, start from the other end and the answer barely changes. Build the same ISMS against the measures in Article 21(2), stand up the reporting flow, and treat certification as a later step you take when a tender demands it. Either way the board funds one system, once.
What does not work is waiting for the Norwegian NIS2 date. Incorporation through the EEA agreement is in progress, no date is announced, and the supply-chain questionnaires are not waiting for it.
Next step
Read how each rule reaches you in our explainers on what NIS2 is, and which Norwegian businesses fall under it and what ISO 27001 is, and why tenders require it. Or talk to our compliance practice for a 30-minute view on which deadline should set your order.
If you are a small or medium-sized business without your own security team, Secured by FM CyberSecurity builds the management system for you, takes you from zero to certification-ready in four to six weeks, and produces the NIS2 documentation from the same work.
Drafted with AI assistance, reviewed and edited by Johan Vorgaard and the FM CyberSecurity editorial team.
FAQ
Does ISO 27001 certification make us NIS2 compliant?
No. NIS2 is law with its own duties, and no certificate satisfies it on its own. The overlap in the underlying work is still large: an ISMS that holds up in an ISO 27001 audit already covers most of the security measures NIS2 lists in Article 21(2). What remains is mostly the incident-reporting procedure and the management body’s formal responsibility.
Do we need a certification to comply with NIS2?
No. NIS2 does not require ISO 27001 or any other certificate. Supervision sits with the authorities. The certificate still pays off commercially, because customers accept it as proof of the same underlying system.
What does NIS2 require that ISO 27001 does not?
Two things: incident reporting with legal deadlines (an early warning within 24 hours, a notification within 72 hours, a final report within a month) and personal accountability for the management body, with duties to approve the measures, follow them up and take training. Both are additions to an ISMS that already stands, and neither replaces it.
When does NIS2 start to apply in Norway?
No date is set. Norway is in the EEA, so the directive has to be incorporated into the EEA agreement and then written into Norwegian law, and that process is in progress. Treat any date you see online as unconfirmed, and expect the duties to reach you earlier through the contracts of covered customers.